Western Digital WD My Book Live (2.x and later) and WD My Book Live Duo (all versions) have an administrator API that can perform a system factory restore without authentication, as exploited in the wild in June 2021, a different vulnerability than CVE-2018-18472.
2021-06-29T21:15:07.880
2024-11-21T06:12:47.760
Modified
CVSSv3.1: 7.5 (HIGH)
AV:N/AC:L/Au:N/C:N/I:N/A:P
10.0
2.9
| Type | Vendor | Product | Version/Range | Vulnerable? | 
|---|---|---|---|---|
| Operating System | westerndigital | wd_my_book_live_firmware | ≥ 2.0 | Yes | 
| Hardware | westerndigital | wd_my_book_live | - | No | 
| Operating System | westerndigital | wd_my_book_live_duo_firmware | * | Yes | 
| Hardware | westerndigital | wd_my_book_live_duo | - | No |